feat(access): verified Bolt Card session at entry + hidden-by-default balance #93
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/boltcard-session-balance"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Tap-to-enter now opens a verified session on the card server instead of soft entry, and shows the holder their card wallet balance.
Session. The tap's single-use SUN is spent once on the boltcards fork's new /session endpoint, which proves a genuine, non-replayed card and returns the wallet balance plus the hit-keyed LUD-03 withdraw and LUD-06 pay second steps. Complete still needs no second tap; the ATM holds no p/c for the visit. The session stays single-shot (dropped after the first Complete attempt). A withheld withdraw step (daily limit spent) declines with the server's reason. Wire contract: docs/boltcard-session.md.
Balance, hidden by default. CardChip shows the card label with the balance masked and an eye toggle. Revealed, it mirrors the LNbits wallet page: sats, then the fiat equivalent (Intl currency formatting) in the wallet's own currency, else the instance default, else the ATM's fiat at its display rate. On the idle menu and both cash screens; resets on re-lock.
Trust boundary, unchanged. The session URL comes from the card's own lnurlw host, so with open enrollment a forged tag naming a cooperative server still unlocks the gate. Money is unaffected. #91 stays open; pinning accepted card-server hosts is the fix.
Depends on aiolabs/boltcards
/session(feat/card-session-endpoint) being deployed on the card server before this merges.Typecheck clean; machine 109 tests; full Electron build green.